GDPR & EU Privacy CompliantLast updated: August 2026

Privacy Policy

Templa is built on a privacy-first foundation with an automated 1-hour file retention policy. We process your documents and keep generated outputs strictly for a temporary 1-hour download window before permanent automated purging.

1-Hour Auto-Purge Lifecycle

Generated DOCX and PDF documents are retained on server disks for 1 hour for download convenience, then permanently purged by automated cleanup cron jobs.

Client-Side Privacy

Template schemas, form drafts, and local preferences remain securely stored in your browser.

Minimal OAuth Scope

We only retrieve your basic profile (email, name, avatar) strictly for identity management.

Full GDPR Rights

You retain total control to access, rectify, export, or delete your account, templates, and workspace data anytime.

1. Introduction & Privacy Philosophy

Welcome to Templa. We are dedicated to providing next-generation document generation and Word (.docx) template automation while uncompromisingly safeguarding your privacy. This Privacy Policy outlines how Templa ('we', 'our', or 'us') handles personal information, template files, and compiled documents in full compliance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and international data protection standards.

2. Information We Process

We deliberately minimize the collection of personal data to the bare minimum required to deliver our services:

1Account Credentials: When you sign in via Google OAuth 2.0, we receive your verified email address, full name, and avatar image. We do not receive or store your Google password.
2Workspace & Template Metadata: Template names, variable schema definitions (placeholders), and workspace configurations necessary to render form interfaces.
3Ephemeral Document Buffers: Uploaded .docx template files and input payload variables provided during document generation.
4Technical Telemetry: IP addresses, browser user-agent, and system logs recorded for rate limiting, anti-abuse protection, and service health monitoring.

3. Temporary File Storage & 1-Hour Auto-Purge Policy

To allow you and your team to preview and download generated documents, Templa maintains a strictly defined temporary retention policy:

Compiled documents (DOCX and PDF) are stored in secure, isolated workspace directories for a maximum of 1 hour (3600 seconds). An automated background cleanup worker runs hourly to permanently delete expired files from disk and erase their file paths from the database. Temporary conversion buffers in system storage are wiped immediately. Once deleted, documents cannot be recovered.

4. Cookies & Local Storage Technologies

We utilize strictly necessary cookies and local browser storage to operate Templa. Non-essential analytics cookies are disabled by default and only activated upon your explicit consent pursuant to Directive 2002/58/EC (ePrivacy Directive).

5. Legal Basis for Processing (GDPR Art. 6)

We process your personal data under the following legal bases:

Contractual Necessity (Art. 6(1)(b) GDPR): To create your account, authenticate sessions, process templates, and provide document compilation services.
Legitimate Interests (Art. 6(1)(f) GDPR): To safeguard system security, prevent denial-of-service abuse, enforce rate limits, and maintain high infrastructure availability.
Explicit Consent (Art. 6(1)(a) GDPR): For optional performance/analytics cookies, which can be withdrawn at any time.

6. Your Rights Under GDPR & EU Law

As a data subject in the European Economic Area (EEA) and globally, you hold extensive rights over your personal data:

Right of Access (Art. 15 GDPR): Request confirmation and a copy of the personal data we hold about you.
Right to Rectification (Art. 16 GDPR): Correct any inaccurate or incomplete personal information.
Right to Erasure / 'Right to be Forgotten' (Art. 17 GDPR): Request immediate deletion of your account, workspace data, and API keys.
Right to Restrict Processing (Art. 18 GDPR): Limit how we process your personal data under certain conditions.
Right to Data Portability (Art. 20 GDPR): Receive your template schemas and configuration data in a structured, machine-readable JSON format.
Right to Object & Withdraw Consent (Art. 21 GDPR): Withdraw consent for analytics cookies or object to legitimate interest processing.

7. Security & Encryption Standards

We apply enterprise-grade security protocols across our entire stack, including TLS 1.3 encryption in transit, strict HttpOnly SameSite authentication cookies, AES-256 encrypted database storage for account credentials, automated rate-limiting throttlers, and regular security vulnerability audits.

8. Subprocessors & Third-Party Services

We partner with trusted infrastructure providers who maintain SOC 2 Type II and ISO 27001 certifications:

Google Cloud Platform / Google OAuth: User authentication and cloud compute infrastructure.
Google Analytics (Optional): Aggregated, anonymized website telemetry (strictly gated by your cookie consent).

9. International Data Transfers

When data is processed outside the European Economic Area, we ensure appropriate safeguards are enacted, including European Commission Standard Contractual Clauses (SCCs) and Data Privacy Framework compliance.

10. Data Protection Officer & Contact

If you have questions regarding this Privacy Policy, wish to exercise your GDPR rights, or need to contact our Data Protection Officer, reach out to us at privacy@templa.io or submit a request via our feedback portal. You also have the right to lodge a complaint with your local EU Data Protection Supervisory Authority.